The official digital operations system for the Reserve Officers' Training Corps, Cagayan State University — Aparri.
Access is restricted to verified personnel. All sessions are monitored and unauthorized access is subject to disciplinary action.
Access Roles
Security Layers
Encrypted
All Systems Operational
Authentication · Records · Session Control
Scroll
Cadet Records
Enrollment & personal information
Attendance Logs
Drill & formation tracking
Merit & Demerit
Tamper-proof conduct ratings
Communications
Orders & unit announcements
System Objective
This platform replaces paper-based ROTC record-keeping with a secure, role-aware digital system — enforcing strict chain-of-identity before any military or academic data is accessed or modified.
Every session is authenticated, scoped to the minimum privilege required, and automatically invalidated after 30 minutes of inactivity — keeping sensitive records out of unauthorized hands.
Threat Response Matrix
↪ Unauthorized external access
Blocked at authentication layer
↪ Internal privilege escalation
Contained by role middleware
↪ Brute-force credential attacks
Stopped by account lockout policy
↪ Session fixation / hijacking
Prevented by ID regeneration
Role-Based Access Control
Every account is bound to exactly one role. Access to data, features, and actions is strictly limited to the scope defined for that role.
Full system control
Complete access over all system resources, user accounts, and unit data.
Unit oversight
Operational access over cadet management, attendance, and unit communications.
Personal records only
Read-only access limited to personal data, attendance history, and announcements.
Cadets may self-register an account to begin enrollment. Admin and officer accounts are issued by system administrators.
Security Architecture
Built around OWASP security principles to protect sensitive military and academic records from misuse, breach, or exploitation.
Accounts lock for 15 minutes after 5 failed login attempts, stopping credential-stuffing and dictionary attacks cold.
30-minute inactivity timeout automatically invalidates sessions, preventing reuse of unattended workstations.
A fresh session ID is issued on every successful login, eliminating session fixation vulnerabilities entirely.
Every route and view is gated by EnsureRole middleware, enforcing least privilege — users can only reach what their role permits.
Minimum 12-character passwords required with mixed case, numbers, and symbols. Stored as bcrypt hashes — never in plaintext.
Deactivated accounts are immediately evicted from any active session on the next request — no grace period.
Sign in with your credentials, or create a cadet account to begin your enrollment application.
New cadet? View enrollment requirements before creating your account.